What you need to know today.
CISA adds six exploited vulnerabilities to KEV, including critical flaws in Citrix NetScaler, Microsoft SQL Server, and Gitea, while Adobe and Ubiquiti face multiple critical issues.

CISA has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a critical memory overflow in Citrix NetScaler ADC and Gateway (CVE-2026-8452), which is being actively exploited in the wild. This flaw allows for denial of service when the appliance is configured as a Gateway. Additionally, a remote code execution vulnerability in Microsoft SQL Server (CVE-2019-1068) has been added, stemming from improper handling of internal functions. The catalog also includes a critical RCE vulnerability in Go Gitea (CVE-2026-60004) affecting versions prior to 1.27.1, which can be exploited via the diffpatch API through Git hook installation. This Gitea flaw is also being actively exploited, with attackers deploying miner-like payloads as reported by The Hacker News. The list further comprises a deserialization vulnerability in the Ajaxpro.2 Project (CVE-2021-23758) leading to RCE, a Linux kernel out-of-bounds write flaw (CVE-2022-0995) that could allow local privilege escalation, and a WordPress RCE vulnerability (CVE-2026-78286) due to unauthenticated PHP object injection.
Adobe Campaign Classic (ACC) is facing multiple critical vulnerabilities, including Server-Side Request Forgery (SSRF) flaws (CVE-2026-76193, CVE-2026-47938) that could lead to arbitrary code execution or privilege escalation. An incorrect authorization vulnerability (CVE-2026-48303) also exists, potentially allowing arbitrary code execution. These vulnerabilities affect versions up to 7.4.3 build 9394. Meanwhile, Ubiquiti UniFi OS devices are impacted by critical vulnerabilities, including an Improper Neutralization of CRLF Sequences flaw (CVE-2026-77550) that could bypass authentication and an Improper Access Control vulnerability (CVE-2026-77536) that could allow privilege escalation. These issues highlight significant risks for organizations relying on these platforms, as detailed by Cyber Security News.
Cisco Systems is addressing critical vulnerabilities in its Secure Firewall Management Center (FMC) Software, including an authentication bypass flaw (CVE-2026-20079) that allows unauthenticated, remote attackers to execute script files and gain root access. This vulnerability has been exploited in the wild as a zero-day, as reported by SecurityWeek. Additionally, Trendnet TEW-821DAP devices running version 2.2.01b05 are affected by a command injection vulnerability (CVE-2026-77946) in the NTP Timezone Configuration Handler component. Other notable vulnerabilities include an unauthenticated authentication bypass in Joomla extensions from miniOrange.com (CVE-2026-77998) and a critical vulnerability in Ozols Grupa OZOLS on Windows (CVE-2026-22306) related to abandoned auto-update domains.